URLhaus Database

You are currently viewing the URLhaus database entry for https://callonenergy.com/swap/ulti_final.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:995137
URL: https://callonenergy.com/swap/ulti_final.exe
URL Status:Offline
Host: callonenergy.com
Date added:2021-02-08 12:43:15 UTC
Last online:2021-02-11 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-02-08 12:44:03 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:3 days, 4 hours, 54 minutes Bad (down since 2021-02-11 17:38:46 UTC)
Tags:exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-10n/aexe a7cb2a5bae04a54229947c343fa4a3d5acada6539ecae81d0eb720e5b5c91928n/a 
2021-02-10n/aexe 7be60a66ead3d6b9276375c6c31eb2103988f649bee2e8c8ac4a5c5754e1ee54n/a 
2021-02-10n/aexe 43e822b13a61ebb00fdcf62f6404dc07d09432f142dbd00dd3bc055ee50eef4en/a 
2021-02-10n/aexe 939ec73afbfaa2455918e951028daadfbba25e30c9051cd4538672d11c29db82n/a 
2021-02-09n/aexe 8005d4e576b99d54054492edbb43407a5d7d8fc723d976d33918d63dbe2e0e96n/a
2021-02-08n/aexe cd5acb3d392233bc5608a66a7614a49b20fe9531594e7ba0621d193e816dd7e4Virustotal results 56.34%